Search/CVE-2006-6682
CVE

CVE-2006-6682

Pedro Lineu Orso chetcpasswd 2.3.3 provides a different error message when a request with a valid username fails, compared to a request with an invalid username, which allows remote attackers to determine valid usernames on the system.

CVSS v3.1
EPSS
1.96%
probability of exploitation in 30 days
CISA KEV
Not listed
no confirmed exploitation reported
News coverage
0
sources referencing this CVE
EPSS Trend
Aug 16, 2026Sep 19, 2026
0.02pp
1.94% → 1.96% over 2 tracked changes
Connections
2 relationships
Timeline
disclosure → media coverage
Dec 21, 2006
Disclosure — published as a CVE record. · last revised by NVD Apr 23, 2026